CVE-2016-9793: Linux Kernel

High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUFFORCE or (2) SO_RCVBUFFORCE option.

Affected products

  • Linux Linux Kernel: from 3.5, before 3.12.69 (fixed in 3.12.69); from 3.13, before 3.16.40 (fixed in 3.16.40); from 3.17, before 3.18.52 (fixed in 3.18.52); from 3.19, before 4.1.50 (fixed in 4.1.50); from 4.2, before 4.4.38 (fixed in 4.4.38); from 4.5, before 4.8.14 (fixed in 4.8.14)

Published 2016-12-28. Last modified 2026-06-17.